Wasn’t it the case with the previous point release as well?
I think the default, at least at the Gateway, should be a disabled clipboard. Most users will not need to do anything on the Gateway ever apart from running apt-get updates or launching Onion Circuits. It is fair that advanced modifications require VirtualBox settings modifications as well.
I also noticed that the default option in “Close Virtual Machine” is “Save the machine state” rather than “Power off the machine”. Is this intended?
Wasn’t it the case with the previous point release as well?
It indeed was.
I think the default, at least at the Gateway, should be a disabled clipboard. Most users will not need to do anything on the Gateway ever apart from running apt-get updates or launching Onion Circuits. It is fair that advanced modifications require VirtualBox settings modifications as well.
Useful for copying bridges or other config (onion services…) to the
gateway. Otherwise major usability hassle.
On
in footnote we say:
“Since Whonix-Gateway is not supposed to be used as a workstation. No
internet facing client application are being used there. Whatever
“leaked” to Whonix-Gateway stays there and since conceptually users do
not use browsers or similar on Whonix-Gateway, it cannot leak anywhere.”
I also noticed that the default option in “Close Virtual Machine” is “Save the machine state” rather than “Power off the machine”. Is this intended?
No. But may also most likely not be possible to modify by using a
VirtualBox ova file since that may be a global VirtualBox rather than
VirtualBox VM specific setting.
Personally I prefer having the strictest possible settings as default, as long as it’s not a hassle to revise them when necessary. In this case I will disable the clipboard on the Gateway, and if I need to copy bridges etc it will take me a few seconds to change it on Virtualbox. When the task is done, I will disable it back. Leaks - my concern is more regarding a leak to the other direction - from the gateway to the workstation / host. For example IP / onion circuit details / private keys of onion services. I don’t know how likely it is to those to get into the clipboard by mistake or carelessness but since the cost of switching it back and forth is minimal…
I can see the reasoning. Not having usability would be a nightmare for first time Whonix/linux users. Is there other functionality that would be helpful to have for first time users?
If you can think of anything that needs documented (e.g. enable $this VirtualBox functionality/utility) or should be included by default, please add to: